vpnc disconnects after 57 minutes during rekey

Asked by spinylumpsucker

This problem is reproducable on vpnc_0.5.3r512-2ubuntu1_amd64.deb, but may exist on any 0.5.3r512 release.

We are connecting to a Cisco ASA 5500 series VPN controlled.

Connections behave correctly until approximately 57 minutes after initiation.
The failure seems to occur during a n attempt to "rekey" with the controller.
From the Cisco controller logs:

Sep 17 11:03:44 vpn-nj-int %ASA-5-713041: Username = test, IP =, IKE Initiator: Rekeying Phase 1, Intf outside, IKE Peer local Proxy Address, remote Proxy Address, Crypto map (N/A)
Sep 17 11:04:16 vpn-nj-int %ASA-5-713259: Group = research, Username = test, IP =, Session is being torn down. Reason: Lost Service
Sep 17 11:04:16 vpn-nj-int %ASA-4-113019: Group = research, Username = test, IP =, Session disconnected. Session Type: IPsecOverNatT, Duration: 0h
:57m:36s, Bytes xmt: 674349, Bytes rcv: 574596, Reason: Lost Service

This appears to be a reintroduction of an earlier bug.

Does anyone have a patch or know of a work around?

Question information

English Edit question
Ubuntu vpnc Edit question
No assignee Edit question
Last query:
Last reply:
Revision history for this message
actionparsnip (andrew-woodhead666) said :

Have you tried connecting to the VPN using network manager?

Revision history for this message
spinylumpsucker (bill-nec-labs) said :

Yes using the network-manager-vpnc package.
Note that this issue seems related to https://bugs.launchpad.net/ubuntu/+source/vpnc/+bug/479632.

Revision history for this message
Ralph Schmieder (ralph-schmieder) said :

I've written a patch that addresses this problem (plus some other enhancements). Please see


for the patch and some explanation.

https://bugs.launchpad.net/ubuntu/+source/vpnc/+bug/479632 mentions that this is fixed ('this bug is closed, and the fix has been in Ubuntu since vpnc/0.5.3r449-2.1 (likely 11.04)'). However, the phase 1 rekey was definitely missing.

Can you help with this problem?

Provide an answer of your own, or ask spinylumpsucker for more information if necessary.

To post a message you must log in.